Free cyber tool

SMB1001 self-assessment

Answer five quick questions about your business and get an indicative SMB1001 tier readiness, plus exactly what to fix in each control area to reach the next tier.

Indicative only, takes about two minutes

SMB1001 is the Australian cyber security standard for small and medium businesses, maintained by Dynamic Standards International. It organises its controls into five areas, and certification at a tier means meeting that tier across all five. Your readiness is therefore set by your weakest area, so this tool scores each one and shows where you stand.

Standard by
Dynamic Standards International

InterIntra is not a certifying body. SMB1001 is maintained by Dynamic Standards International and certificates are issued through the CyberCert portal. We do the gap analysis, remediation and evidence.

Question 1 of 5
1 Technology Management

How are your devices, operating systems and applications kept current and securely configured?

2 Access Management

How is access to your systems controlled, and where is multi-factor authentication enforced?

3 Backup & Recovery

How are your backups run, protected from ransomware, and proven to actually restore?

4 Policies & Processes

What security policies, incident response and supplier requirements do you have documented?

5 Education & Training

What security awareness training do your staff actually receive?

What is SMB1001?

SMB1001 is an Australian cyber security standard written specifically for small and medium businesses, maintained by Dynamic Standards International (DSI). The current version is SMB1001:2025. Where frameworks like ISO 27001 assume a dedicated security function and a budget to match, SMB1001 was built for businesses of roughly 5 to 200 staff, and it certifies in progressive tiers so a smaller business can reach a real, usable outcome without a two-year programme.

It also aligns deliberately with the ACSC Essential Eight, the UK's Cyber Essentials scheme and elements of the US CMMC, which is why it works as a stepping stone toward ISO 27001 rather than a dead end. This free tool gives you an indicative tier readiness in about two minutes, with no sign-up.

The five control areas

SMB1001 organises its controls into five coverage areas. Certification at a tier means meeting that tier's requirements across all five, which is why your readiness is set by your weakest area rather than your average.

The SMB1001 tiers explained

There are five progressive tiers. The important distinction for planning is where independent assessment begins.

Why SMB1001 matters for Australian businesses

Cyber security questions have moved into procurement. Larger clients ask suppliers to demonstrate a security posture, insurers ask at renewal, and government-adjacent work increasingly expects something more than a verbal assurance. For a business of 20 or 50 people, ISO 27001 is often disproportionate, and an Essential Eight maturity score is useful internally but harder to hand to a client as evidence. SMB1001 produces a shareable certificate and digital badge, which is a concrete answer to a procurement question.

We are ISO 27001 certified ourselves, so the evidence discipline SMB1001 asks for is how we already work rather than something we advise on from a distance.

How this self-assessment works

You answer one question per control area, choosing the option that best describes where you genuinely are today. Each answer maps to a readiness band, and your overall indicative tier is the lowest band across the five areas, mirroring how tiered certification actually works. The breakdown then shows, for each area, the specific step that would lift it to the next tier.

This is indicative only. It is based on a single question per control area and verifies no evidence, so treat it as a way to see roughly where you stand before committing to a formal gap analysis. A real gap analysis tests each control against the full standard and, crucially, tests whether your evidence would satisfy an assessor.

Frequently asked questions

SMB1001 is an Australian cyber security standard written specifically for small and medium businesses, maintained by Dynamic Standards International (DSI). The current version is SMB1001:2025. It organises its controls into five areas: technology management, access management, backup and recovery, policies and processes, and education and training. It was designed for businesses of roughly 5 to 200 staff and deliberately aligns with the ACSC Essential Eight, the UK's Cyber Essentials scheme and elements of the US CMMC.

There are five progressive tiers: Bronze, Silver, Gold, Platinum and Diamond. Bronze, Silver and Gold are attested by a company director through the CyberCert portal. Platinum and Diamond require independent third-party assessment, where an accredited assessor verifies your controls and evidence before certification is issued. Because certification at a tier means meeting that tier across all five control areas, your readiness is set by your weakest area.

No. This is a free, indicative self-assessment to show roughly where you stand and what to fix first. It asks one question per control area and does not verify any evidence. Actual certification is issued through the CyberCert portal, with Bronze, Silver and Gold attested by a company director and Platinum and Diamond independently audited. InterIntra can run a proper gap analysis against the full standard and manage the remediation and evidence.

No, and no self-assessment can. Platinum and Diamond require an accredited third-party assessor to verify your controls and evidence, so the outcome depends on that assessment rather than on your own view of your controls. This tool indicates readiness up to Gold, which is the highest director-attested tier. If you are targeting the audited tiers, the useful next step is a gap analysis that tests your evidence the way an assessor will.

Yes, the tool is completely free and there is no sign-up. You answer the five questions in your browser and your results appear instantly. Nothing is stored or sent, and we never ask for your email to show your result.

About two minutes. There are five questions, one for each SMB1001 control area, and your indicative tier readiness and per-area breakdown update as you answer.